Data Processing Addendum (DPA)

Effective Date: September 28, 2026 • Timesink Oy (Finland)

1. Scope and Relationship of the Parties

This Data Processing Addendum (“DPA”) supplements the TimesinkDB Terms of Service entered into between Timesink Oy (“Processor” or “TimesinkDB”), a Finnish limited liability company (Business ID 3658114-2, VAT FI36581142, Tampere, Finland), and the customer identified in the account registration (“Controller” or “Customer”).

This DPA applies whenever TimesinkDB processes personal data on behalf of Customer in connection with Customer’s provisioned databases, telemetry ingestion pipelines, or analytical queries within the TimesinkDB Service, pursuant to Article 28 of Regulation (EU) 2016/679 (EU GDPR) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018). For personal data collected directly by TimesinkDB during pre-launch reservations, account registration, or website visits where TimesinkDB acts as Data Controller, please refer to our Privacy Policy.

2. Subject Matter, Duration, and Nature of Processing

Subject Matter: The provision of high-performance embedded time-series storage, high-throughput batch metric ingestion, JSON event logging, downsampling calculations, and HTTP query API services.

Duration: The term of Customer’s active subscription or free sandbox account until all Customer databases and associated storage volumes are deleted.

Categories of Data: Time-series telemetry points, Unix timestamps, numeric sensor values, and arbitrary JSON payloads ingested via Customer’s API keys or webhook endpoints. Customer determines the exact payload data ingested.

Data Subjects: End users, customers, system operators, or connected devices whose telemetry data Customer transmits to the TimesinkDB service.

3. Processor Obligations

TimesinkDB covenants that it shall:

  • Documented Instructions: Process Customer telemetry data strictly in accordance with documented instructions from Customer (including API ingestion calls and configuration updates) and not for any secondary profiling, advertising, or model training purposes.
  • Confidentiality: Ensure that all personnel authorized to access Customer storage volumes are bound by statutory and contractual non-disclosure and confidentiality obligations.
  • Strict Multi-Tenant Isolation: Enforce strict logical and physical tenant isolation through segregated storage directories, isolated database runtimes, dedicated memory management, and per-database cryptographic authentication credentials to prevent unauthorized cross-tenant data access.
  • Data Subject Assistance: Provide Customer with automated self-service controls, granular time-to-live (TTL) retention rules, and administrative deletion capabilities to fulfill GDPR data subject rights including erasure (right to be forgotten) and rectification.

4. Technical and Organizational Measures (TOMs)

TimesinkDB implements and maintains state-of-the-art security measures to protect Customer data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:

Encryption in Transit & at Rest

All data in transit is encrypted using mandatory TLS 1.3 / TLS 1.2 with modern cipher suites and perfect forward secrecy. All persistent storage volumes use industry-standard volume-level encryption at rest (AES-256).

Workload & Memory Isolation

Dedicated memory buffers and partitioned tenant runtimes enforce complete separation between customer databases, preventing cross-tenant data retention or memory leakage.

Strong Cryptographic Authentication

Cryptographically strong hashed API credentials and optional mutual TLS (mTLS) client certificate authentication ensure that only authorized clients can query or ingest data.

Network Allowlisting & Edge Protection

Optional database-level CIDR IP allowlisting combined with edge Anycast protection guarantees automated mitigation of DDoS and volumetric network attacks.

5. Sub-Processors

Customer provides general written authorization for TimesinkDB to engage the following sub-processors for the delivery of infrastructure, edge routing, and payment processing:

Sub-Processor Role / Service Data Location
Microsoft Corporation (Microsoft Azure) Primary Cloud Compute, Virtualized Infrastructure, Central Control Plane (Frankfurt), Regional Storage, Capacity Reservations & Platform Communications Services EU (Frankfurt, Germany), North America, Asia-Pacific & customer-selected Dedicated regions
Cloudflare, Inc. Edge CDN, Anycast Routing, DDoS Mitigation, TLS Termination, Edge Caching, Web Hosting & Edge Serverless / Persistence Services Global Anycast Network (EU-US Data Privacy Framework)
Paddle Payments Limited Merchant of Record, Subscription Checkout, Invoicing & Global Tax/VAT Compliance Ireland (EU) / United Kingdom / Global

TimesinkDB shall provide at least thirty (30) days notice via email or console notification prior to onboarding a new infrastructure sub-processor, giving Customer the opportunity to object on reasonable privacy grounds.

6. Personal Data Breach Notification

In the event of a confirmed Personal Data Breach affecting Customer data, TimesinkDB shall notify Customer without undue delay and, in any event, not later than forty-eight (48) hours after becoming aware of the breach.

The notification shall describe the nature of the breach, the categories and approximate number of affected data records, the likely consequences, and the mitigation measures taken or proposed.

7. Return and Deletion of Data

For individual series data erasure (GDPR Art. 17), deletion requests immediately exclude target telemetry from query execution and analytical retrieval, with physical storage space reclaimed during routine background maintenance cycles. Upon termination of Customer’s account or full database deletion, Customer data is handled as follows:

  • All customer storage partitions, metadata catalogs, and associated database files are immediately unlinked from the active service runtime and permanently decommissioned.
  • Allocated storage blocks are released back to cloud infrastructure storage pools in accordance with industry-standard cloud storage deallocation and data sanitization standards.
  • Automated disaster recovery snapshots and rolling system backups are securely overwritten and purged within thirty (30) calendar days in accordance with our disaster recovery retention schedule.

8. Governing Law and Signatures

This DPA shall be governed by and construed in accordance with the laws of Finland. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the District Court of Pirkanmaa (Pirkanmaan käräjäoikeus) in Tampere, Finland.

For customers requiring a countersigned copy of this DPA, please send your executed agreement or request to legal@timesinkdb.com.